May 21, 2023, 9:48 a.m. | /u/elnano005

cybersecurity www.reddit.com

Hi everyone,
I am noticing lately on Azure sign in logs there are multiple bruteforce attempts from malicious IP on 'high risk' users on 'Microsoft Azure CLI' application with failure reason 'Sign-in was blocked due to real-time detection rule(s): TI\_RT\_0015' (error code 500532).
Below the error:
\*\*\*\*\*\*\*\*\*\*\*\*\*
Status: Failure
Continuous access evaluation: No
Sign-in error code: 500532
Failure reason: Sign-in was blocked due to real-time detection rule(s): TI\_RT\_0015
Application: Microsoft Azure CLI
\*\*\*\*\*\*\*\*\*\*\*\*\*
I searched on sign-in logs on Sentinel …

application azure blocked bruteforce cli code cybersecurity detection error high logs malicious microsoft microsoft azure risk sign

Security Engineer

@ Celonis | Munich, Germany

Security Engineer, Cloud Threat Intelligence

@ Google | Reston, VA, USA; Kirkland, WA, USA

IT Security Analyst*

@ EDAG Group | Fulda, Hessen, DE, 36037

Scrum Master/ Agile Project Manager for Information Security (Temporary)

@ Guidehouse | Lagunilla de Heredia

Waste Incident Responder (Tanker Driver)

@ Severn Trent | Derby , England, GB

Risk Vulnerability Analyst w/Clearance - Colorado

@ Rothe | Colorado Springs, CO, United States